INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Mythos Era Bug Bounty Program Exploited by Lazarus Group
| 2026-06-11 00:00 HIGH LOW EXPLOITED VULNERABILITY STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A bug bounty submission was received by the company shortly after related materials were published, with a suspiciously timed submission from researchers at Code White in Germany. The researcher claimed to be based in Japan but their device's IP location was geolocated to China, where the epicenter of Pacific Rim activity is identified as being located. This incident affected 7,091 total submissions and resulted in one vulnerability being discovered, with a reward paid out for this specific finding. The attack works by utilizing AI-assisted research tools that flood programs with low-signal 'slop', while also producing validated vulnerabilities at machine speed. As of the writing date, the company has paid out $599,695 in rewards for 1,343 vulnerabilities discovered through their bug bounty program since its launch on December 14, 2017.
Technical Mitigations AI-generated
• Use validated, reproducible exploit hypotheses to improve the effectiveness of bug bounty programs.
• Implement techniques that reason across codebases and build non-obvious chains to detect vulnerabilities at machine speed.
• Block or hunt for low-effort, AI-assisted submissions with a high false positive rate.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2022-1040CVE-2022-1040
CVE-2020-15504CVE-2020-15504
CVE-2020-12271CVE-2020-12271
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
DACH
DACH
Incident Timeline
December 14, 2017
Threat actors submitted 7,091 vulnerabilities to the Mythos era bug bounty program between December 14, 2017 and this writing.
Click on any entity below to view its context and source!
financial
$599,695 rewards
Since then, we’ve paid out for 1,343 vulnerabilities as of this writing (not quite 1,337!), out of 7,091 total submissions, with the rewards totalling $599,695.
June 2020
Firmware 18.0 MR1-1 was released in June 2020 with a built-in fix, addressing an issue that occurred prior to its release date.
Click on any entity below to view its context and source!
infrastructure
18.0
Firmware 18.0 MR1-1 released with a built-in fix
July 2020:
July 2020
A researcher claiming to be based in Japan submitted a zero-day vulnerability, CVE-2022-1040, to the bug bounty program one day before it was actively exploited.
Click on any entity below to view its context and source!
infrastructure
17.5
Firmware 17.5 MR13 released with a built-in fix
13.07.2020: Blog post published in coordination with the vendor
From initial report to confirmed reproduction in under 13 hours, and a first hotfix the same day.
infrastructure
13.07.2020
Firmware 17.5 MR13 released with a built-in fix
13.07.2020: Blog post published in coordination with the vendor
From initial report to confirmed reproduction in under 13 hours, and a first hotfix the same day.
financial
$20,000 $ bounty
A pseudonymous researcher, who did not wish to be credited, reported a zero-day to our bug bounty program and received a $20,000 bounty.
January 2026
Researchers at Code White, a Germany-based security company, submitted a SQLi (CVE-2020-15504) vulnerability report through the program that could have been leveraged for RCE.
Click on any entity below to view its context and source!
infrastructure
Windows
And here are some more detailed updates on selected targets:
Intercept X Endpoint (Windows) Special Target
Intercept X Endpoint (Windows) has continued with updated reward amounts and structure to incentivize deeper research.
financial
$80,000 $ Sophos Central
For example, the maximum reward for a single issue is $80,000 for demonstrating zero-click remote code execution (RCE).
financial
$8,000 $ targets
The highest reward of 2025 was $8,000 for a report related to pre-authentication SQL injection (SQLi).
infrastructure
21.05.2020
Researcher reported a possible bypass for the hotfix’s security measures
21.05.2020: Second hotfix released, disabling the pre-auth email quarantine release feature
June 2020:
financial
$9,600 Endpoint
We received seven reports of unique, valid security bugs in Intercept X Endpoint during 2025 and awarded $9,600 in total.
financial
$2,000 report
The highest rewards of 2025 went to one researcher for three reports, with each report receiving $2,000.
financial
$11,650 Central
We received 13 reports of unique, valid security bugs in Sophos Central during 2025 and awarded $11,650 in total.
financial
$5,500 reward
The highest reward of 2025 was $5,500 for a report related to HTTP request smuggling.
financial
$21,500 Firewall
We received 13 reports of unique, valid security bugs in Sophos Firewall during 2025 and awarded $21,500 in total.
2026/06/11
Threat actors exploited a previously unknown SQLi (CVE-2020-12271) leading to RCE on some firewall products.
Click on any entity below to view its context and source!
infrastructure
Windows
Our special targets and corresponding rewards were as follows:
Intercept X Endpoint (Windows): up to $80,000
Sophos Central: up to $50,000
Sophos Firewall: up to $50,000
Premium Bounty Eligible targets: up to $8,000
Catch-all targets: up to $5,000…
financial
$80,000 $ Sophos Central
Our special targets and corresponding rewards were as follows:
Intercept X Endpoint (Windows): up to $80,000
Sophos Central: up to $50,000
Sophos Firewall: up to $50,000
Premium Bounty Eligible targets: up to $8,000
Catch-all targets: up to $5,000
H…
financial
$50,000 $ Sophos Firewall
Our special targets and corresponding rewards were as follows:
Intercept X Endpoint (Windows): up to $80,000
Sophos Central: up to $50,000
Sophos Firewall: up to $50,000
Premium Bounty Eligible targets: up to $8,000
Catch-all targets: up to $5,000
H…
financial
$8,000 $ targets
Our special targets and corresponding rewards were as follows:
Intercept X Endpoint (Windows): up to $80,000
Sophos Central: up to $50,000
Sophos Firewall: up to $50,000
Premium Bounty Eligible targets: up to $8,000
Catch-all targets: up to $5,000
H…
financial
$5,000 $ Intercept X Endpoint
Our special targets and corresponding rewards were as follows:
Intercept X Endpoint (Windows): up to $80,000
Sophos Central: up to $50,000
Sophos Firewall: up to $50,000
Premium Bounty Eligible targets: up to $8,000
Catch-all targets: up to $5,000
H…
financial
$59,400 numbers
Our special targets and corresponding rewards were as follows:
Intercept X Endpoint (Windows): up to $80,000
Sophos Central: up to $50,000
Sophos Firewall: up to $50,000
Premium Bounty Eligible targets: up to $8,000
Catch-all targets: up to $5,000
H…
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
Our special targets and corresponding rewards were as follows:
Intercept X Endpoint (Windows): up to $80,000
Sophos Central: up to $50,000
Sophos Firewall: up to $50,000
Premium Bounty Eligible targets: up to $8,000
Catch-all targets: up to $5,000…
And here are some more detailed updates on selected targets:
Intercept X Endpoint (Windows) Special Target
Intercept X Endpoint (Windows) has continued with updated reward amounts and structure to incentivize deeper research.
Metrics
financial
80,000
$ Sophos Central
Our special targets and corresponding rewards were as follows:
Intercept X Endpoint (Windows): up to $80,000
Sophos Central: up to $50,000
Sophos Firewall: up to $50,000
Premium Bounty Eligible targets: up to $8,000
Catch-all targets: up to $5,000
H…
For example, the maximum reward for a single issue is $80,000 for demonstrating zero-click remote code execution (RCE).
Metrics
financial
50,000
$ Sophos Firewall
Our special targets and corresponding rewards were as follows:
Intercept X Endpoint (Windows): up to $80,000
Sophos Central: up to $50,000
Sophos Firewall: up to $50,000
Premium Bounty Eligible targets: up to $8,000
Catch-all targets: up to $5,000
H…
Metrics
financial
8,000
$ Targets
Our special targets and corresponding rewards were as follows:
Intercept X Endpoint (Windows): up to $80,000
Sophos Central: up to $50,000
Sophos Firewall: up to $50,000
Premium Bounty Eligible targets: up to $8,000
Catch-all targets: up to $5,000
H…
The highest reward of 2025 was $8,000 for a report related to pre-authentication SQL injection (SQLi).
Metrics
financial
5,000
$ Intercept X Endpoint
Our special targets and corresponding rewards were as follows:
Intercept X Endpoint (Windows): up to $80,000
Sophos Central: up to $50,000
Sophos Firewall: up to $50,000
Premium Bounty Eligible targets: up to $8,000
Catch-all targets: up to $5,000
H…
Metrics
financial
59,400
Numbers
Our special targets and corresponding rewards were as follows:
Intercept X Endpoint (Windows): up to $80,000
Sophos Central: up to $50,000
Sophos Firewall: up to $50,000
Premium Bounty Eligible targets: up to $8,000
Catch-all targets: up to $5,000
H…
Metrics
infrastructure
21.05.2020
Software Version
Researcher reported a possible bypass for the hotfix’s security measures
21.05.2020: Second hotfix released, disabling the pre-auth email quarantine release feature
June 2020:
Metrics
infrastructure
18.0
Software Version
Firmware 18.0 MR1-1 released with a built-in fix
July 2020:
Metrics
infrastructure
17.5
Software Version
Firmware 17.5 MR13 released with a built-in fix
13.07.2020: Blog post published in coordination with the vendor
From initial report to confirmed reproduction in under 13 hours, and a first hotfix the same day.
Metrics
infrastructure
13.07.2020
Software Version
Firmware 17.5 MR13 released with a built-in fix
13.07.2020: Blog post published in coordination with the vendor
From initial report to confirmed reproduction in under 13 hours, and a first hotfix the same day.
Metrics
financial
9,600
Endpoint
We received seven reports of unique, valid security bugs in Intercept X Endpoint during 2025 and awarded $9,600 in total.
Metrics
financial
2,000
Report
The highest rewards of 2025 went to one researcher for three reports, with each report receiving $2,000.
Metrics
financial
11,650
Central
We received 13 reports of unique, valid security bugs in Sophos Central during 2025 and awarded $11,650 in total.
Metrics
financial
5,500
Reward
The highest reward of 2025 was $5,500 for a report related to HTTP request smuggling.
Metrics
financial
21,500
Firewall
We received 13 reports of unique, valid security bugs in Sophos Firewall during 2025 and awarded $21,500 in total.
Metrics
financial
599,695
Rewards
Since then, we’ve paid out for 1,343 vulnerabilities as of this writing (not quite 1,337!), out of 7,091 total submissions, with the rewards totalling $599,695.
Metrics
financial
20,000
$ Bounty
A pseudonymous researcher, who did not wish to be credited, reported a zero-day to our bug bounty program and received a $20,000 bounty.
Intelligence Sources
Sophos News
2026-06-11
Bug bounties in the Mythos era
Sophos News
Sophos News
2026-06-11
Bug bounties in the Mythos era
Sophos News
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T12:31
Comprehensive Tactical Telemetry
Highly Correlated Entities
26x
organisation
Identified Entity
IP
entity
10x
timeline
Temporal Reference
2026/06/11
date
4x
infrastructure
Software Version
21.05.2020
version
3x
target region
Target Country
United States
country
3x
vulnerability
Exploited CVE
CVE-2020-12271
cve
2x
source region
Origin Country
China
country
2x
tactic
Cyber Operation Type
Reconnaissance
tactic
2x
general metric
Firmware
18
firmware
Contextual Telemetry
Context Block
23 METRICS
industry
Targeted Sector
Health
sector
infrastructure
Affected Product
Windows
software
financial
$ Sophos Central
80,000
$ sophos central
financial
$ Sophos Firewall
50,000
$ sophos firewall
financial
$ Targets
8,000
$ targets
financial
$ Intercept X Endpoint
5,000
$ intercept x endpoint
financial
Numbers
59,400
numbers
general metric
Reports
52
reports
general metric
Researchers
420
researchers
tactic
MITRE ATT&CK Technique
T1592.003 - Firmware
technique
general metric
Mr13
18
mr13
general metric
Hours
13
hours
financial
Endpoint
9,600
endpoint
financial
Report
2,000
report
financial
Central
11,650
central
financial
Reward
5,500
reward
financial
Firewall
21,500
firewall
general metric
Cisos
250
cisos
general metric
Vulnerabilities
1,343
vulnerabilities
general metric
Writing
1,337
writing
general metric
Total Submissions
7,091
total submissions
financial
Rewards
599,695
rewards
financial
$ Bounty
20,000
$ bounty
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.